Skip to main content
CloudKey

1 actively exploited

FortiGate 5.6.12: known CVEs & fixed releases

9 CVEs affect this build · 1 in CISA KEV (actively exploited) · highest CVSS 9.8 · 2 builds behind the latest 5.6.14 · updated 2026-06-26

Patch path: upgrade to 5.6.13 or 6.0.11 or 6.0.15 or 6.0.16 or 6.0.9 or 6.2.12 or 6.2.13 or 6.2.15 or 6.2.2 or 6.2.5 or 6.4.10 or 6.4.11 or 6.4.12 or 6.4.13 or 6.4.2 or 7.0.10 or 7.0.12 or 7.0.8 or 7.0.9 or 7.2.3 or 7.2.4 or 7.2.5 or 7.2.6 to clear the exploited issues below.

  • KEV · exploited CRITICAL
    CVE-2022-42475

    Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

    Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

    CVSS
    9.8
    EPSS
    99%
    KEV added
    2022-12-13
    Published
    2022-12-13
    Fixed in 6.0.15, 6.0.16, 6.2.12, 6.4.10, 6.4.11, 7.0.8, 7.0.9, 7.2.3 NVD ↗CISA ↗fortiguard.com ↗
  • CRITICAL
    CVE-2023-25610

    CVE-2023-25610

    A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

    CVSS
    9.8
    Published
    2025-03-24
    Fixed in 6.2.13, 6.4.12, 7.0.10, 7.2.4 NVD ↗fortiguard.com ↗
  • CVE-2020-12820

    Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.

    CVSS
    8.8
    Published
    2024-12-19
    Fixed in 5.6.13, 6.0.11 NVD ↗fortiguard.fortinet.com ↗
  • CVE-2023-29181

    A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM 1.0.0 through 1.0.3 allows attacker to execute unauthorized code or commands via specially crafted command.

    CVSS
    8.8
    Published
    2024-02-22
    Fixed in 6.2.15, 6.4.13, 7.0.12, 7.2.5 NVD ↗fortiguard.com ↗
  • CVE-2020-12819

    A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is enabled. Arbitrary code execution may be theoretically possible, albeit practically very difficult to achieve in this context

    CVSS
    7.5
    Published
    2024-12-19
    Fixed in 5.6.13, 6.0.11, 6.2.5, 6.4.2 NVD ↗fortiguard.com ↗
  • CVE-2023-45583

    A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.2, FortiSwitchManager 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.

    CVSS
    7.2
    Published
    2024-05-14
    Fixed in 7.2.6 NVD ↗fortiguard.com ↗
  • CVE-2023-33305

    A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiWeb version 7.2.0 through 7.2.1, FortiWeb version 7.0.0 through 7.0.6, FortiWeb 6.4 all versions, FortiWeb 6.3 all versions allows attacker to perform a denial of service via specially crafted HTTP requests.

    CVSS
    6.5
    Published
    2023-06-13
  • CVE-2019-15706

    An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).

    CVSS
    5.4
    Published
    2025-03-17
    Fixed in 5.6.13, 6.0.9, 6.2.2 NVD ↗fortiguard.fortinet.com ↗
  • CVE-2022-22305

    An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the listed products and some external peers.

    CVSS
    4.2
    Published
    2023-09-01

Stop checking versions by hand

Is your whole fleet exposed, not just this FortiGate?

VulnMonitor reconciles every advisory against your real inventory and ranks what matters by actual exploitation (CISA KEV, EPSS), not raw CVSS. New CVE hits your gear, it is on your queue with the fix attached.

Free to start · no credit card